Записи AMD
302 опубликованных записей вендора amd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 19,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation47
- CWE-787 Out-of-bounds Write30
- CWE-125 Out-of-bounds Read17
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-276 Incorrect Default Permissions10
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
302 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-5049Эксплойта нет | An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.amd · radeon rx 550 firmware · CWE-787 | Критическая10,0 | — | 2,0 % | 31 окт. 2019 г. |
40В плане | CVE-2020-6103Эксплойта нет | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Критическая9,9 | — | 2,7 % | 20 июл. 2020 г. |
40В плане | CVE-2020-6101Эксплойта нет | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Критическая9,9 | — | 2,7 % | 20 июл. 2020 г. |
40В плане | CVE-2020-6102Эксплойта нет | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Критическая9,9 | — | 2,7 % | 20 июл. 2020 г. |
40В плане | CVE-2019-7247Эксплойта нет | An issue was discovered in AODDriver2.sys in AMD OverDrive.amd · overdrive | Критическая9,8 | — | 2,1 % | 18 мая 2020 г. |
40В плане | CVE-2020-6100Эксплойта нет | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Критическая9,9 | — | 2,0 % | 20 июл. 2020 г. |
40В плане | CVE-2023-20591Эксплойта нет | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toamd · epyc 8024pn firmware · CWE-665 | Критическая10,0 | — | 0,3 % | 13 авг. 2024 г. |
39Наблюдать | CVE-2021-26334Эксплойта нет | AMD Chipset Driver Information Disclosure Vulnerabilityamd · amd uprof · CWE-284 | Критическая9,9 | — | 1,2 % | 1 дек. 2021 г. |
39Наблюдать | CVE-2023-20596Эксплойта нет | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadinamd · ryzen 7 5700g firmware | Критическая9,8 | — | 1,0 % | 14 нояб. 2023 г. |
39Наблюдать | CVE-2023-20586Эксплойта нет | Radeon™ Software Crimson ReLive Editionamd · radeon software | Критическая9,8 | — | 1,0 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2022-23821Эксплойта нет | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execamd · ryzen 9 3900 firmware | Критическая9,8 | — | 1,0 % | 14 нояб. 2023 г. |
39Наблюдать | CVE-2023-20520Эксплойта нет | Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun amd · epyc 72f3 firmware · CWE-787 | Критическая9,8 | — | 0,8 % | 9 мая 2023 г. |
39Наблюдать | CVE-2021-46760Эксплойта нет | A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory accesamd · ryzen 3945wx firmware · CWE-119 | Критическая9,8 | — | 0,8 % | 9 мая 2023 г. |
39Наблюдать | CVE-2022-23820Эксплойта нет | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code executamd · ryzen 9 3900 firmware · CWE-20 | Критическая9,8 | — | 0,7 % | 14 нояб. 2023 г. |
39Наблюдать | CVE-2021-26379Эксплойта нет | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a amd · epyc 72f3 firmware | Критическая9,8 | — | 0,7 % | 9 мая 2023 г. |
39Наблюдать | CVE-2023-39281Эксплойта нет | A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to runinsyde · insydeh2o · CWE-787 | Критическая9,8 | — | 0,5 % | 1 нояб. 2023 г. |
37Наблюдать | CVE-2019-5183Эксплойта нет | An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031amd · atidxx64 · CWE-843 | Критическая9,0 | — | 1,8 % | 25 янв. 2020 г. |
37Наблюдать | CVE-2018-8930Эксплойта нет | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERamd · ryzen mobile firmware | Критическая9,0 | — | 1,8 % | 22 мар. 2018 г. |
37Наблюдать | CVE-2018-8936Эксплойта нет | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.amd · ryzen mobile firmware | Критическая9,0 | — | 1,8 % | 22 мар. 2018 г. |
37Наблюдать | CVE-2018-8935Эксплойта нет | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.amd · ryzen pro firmware | Критическая9,0 | — | 1,8 % | 22 мар. 2018 г. |
37Наблюдать | CVE-2018-8934Эксплойта нет | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.amd · ryzen pro firmware | Критическая9,0 | — | 1,8 % | 22 мар. 2018 г. |
36Наблюдать | CVE-2020-12138Эксплойта нет | AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routineamd · atillk64 · CWE-862 | Высокая8,8 | — | 3,3 % | 27 апр. 2020 г. |
36Наблюдать | CVE-2018-8932Эксплойта нет | The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZamd · ryzen pro firmware · CWE-732 | Критическая9,0 | — | 1,7 % | 22 мар. 2018 г. |
36Наблюдать | CVE-2018-8931Эксплойта нет | The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.amd · ryzen mobile firmware · CWE-732 | Критическая9,0 | — | 1,7 % | 22 мар. 2018 г. |
36Наблюдать | CVE-2018-8933Эксплойта нет | The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.amd · epyc server firmware · CWE-732 | Критическая9,0 | — | 1,7 % | 22 мар. 2018 г. |
- CVE-2019-504941В плане
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %amd · radeon rx 550 firmware31 окт. 2019 г.
- CVE-2020-610340В плане
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %amd · radeon directx 11 driver atidxx64.dll20 июл. 2020 г.
- CVE-2020-610140В плане
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %amd · radeon directx 11 driver atidxx64.dll20 июл. 2020 г.
- CVE-2020-610240В плане
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %amd · radeon directx 11 driver atidxx64.dll20 июл. 2020 г.
- CVE-2019-724740В плане
An issue was discovered in AODDriver2.sys in AMD OverDrive.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amd · overdrive18 мая 2020 г.
- CVE-2020-610040В плане
An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %amd · radeon directx 11 driver atidxx64.dll20 июл. 2020 г.
- CVE-2023-2059140В плане
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %amd · epyc 8024pn firmware13 авг. 2024 г.
- CVE-2021-2633439Наблюдать
AMD Chipset Driver Information Disclosure Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %amd · amd uprof1 дек. 2021 г.
- CVE-2023-2059639Наблюдать
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · ryzen 7 5700g firmware14 нояб. 2023 г.
- CVE-2023-2058639Наблюдать
Radeon™ Software Crimson ReLive Edition
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · radeon software8 авг. 2023 г.
- CVE-2022-2382139Наблюдать
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code exec
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · ryzen 9 3900 firmware14 нояб. 2023 г.
- CVE-2023-2052039Наблюдать
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · epyc 72f3 firmware9 мая 2023 г.
- CVE-2021-4676039Наблюдать
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory acces
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · ryzen 3945wx firmware9 мая 2023 г.
- CVE-2022-2382039Наблюдать
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execut
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · ryzen 9 3900 firmware14 нояб. 2023 г.
- CVE-2021-2637939Наблюдать
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amd · epyc 72f3 firmware9 мая 2023 г.
- CVE-2023-3928139Наблюдать
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %insyde · insydeh2o1 нояб. 2023 г.
- CVE-2019-518337Наблюдать
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · atidxx6425 янв. 2020 г.
- CVE-2018-893037Наблюдать
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTER
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen mobile firmware22 мар. 2018 г.
- CVE-2018-893637Наблюдать
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen mobile firmware22 мар. 2018 г.
- CVE-2018-893537Наблюдать
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen pro firmware22 мар. 2018 г.
- CVE-2018-893437Наблюдать
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen pro firmware22 мар. 2018 г.
- CVE-2020-1213836Наблюдать
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routine
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %amd · atillk6427 апр. 2020 г.
- CVE-2018-893236Наблюдать
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZ
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen pro firmware22 мар. 2018 г.
- CVE-2018-893136Наблюдать
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · ryzen mobile firmware22 мар. 2018 г.
- CVE-2018-893336Наблюдать
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %amd · epyc server firmware22 мар. 2018 г.